SLAVUL: A Novel Ontology-Driven Approach for Integrating Cloud SLA Security Knowledge and Vulnerability Intelligence
Ozgu Can, Sena YakutCloud Service Level Agreements (SLAs) define security obligations, remediation commitments, and compliance requirements between cloud service providers and customers. SLAs define the performance standards and expectations between service providers and users. Therefore, it is an essential element in cloud computing. However, SLA documents are typically represented in unstructured natural language and lack semantic integration with operational vulnerability management processes. Meanwhile, cloud security platforms continuously generate vulnerability intelligence containing security findings, severity levels, and remediation information. The lack of semantic interoperability between SLA-defined security obligations and vulnerability intelligence limits automated security governance, compliance assessment, and vulnerability management in cloud environments. To address these challenges, this study proposes an integrated semantic approach that enables the representation, integration, and reasoning of SLA-derived security knowledge and cloud vulnerability intelligence within a unified ontology model. The proposed solution combines automated knowledge acquisition from SLA documents, the development of an SLA Security Ontology and a Vulnerability Ontology, ontology alignment techniques, and Semantic Web Rule Language (SWRL)-based reasoning mechanisms to support automated vulnerability management, remediation commitment assignment, and consistency verification. Further, the proposed approach is evaluated using real-world SLA documents and vulnerability information. Experimental results demonstrate that the developed reasoning mechanism successfully identifies logical inconsistencies in 73% of the evaluated SLA cases. The analysis further reveals that the undetected cases correspond to contractually incorrect yet logically consistent outputs, highlighting the complementary role of human validation in ontology-driven security management. As a result, the study demonstrates that ontology engineering and rule-based semantic reasoning can effectively bridge the gap between contractual security obligations and operational vulnerability intelligence. Therefore, the proposed approach provides a foundation for automated vulnerability management, SLA compliance assessment, and semantically aware cloud security governance.